Trust & Security
The Vault is custody infrastructure. Trust is not a marketing claim — it is something you should be able to verify. This page collects the independent assessments we are pursuing, the controls already in place, and the technical artifacts we share — our security posture openly, and the full specifications under NDA — so you do not have to take our word for any of it.
Status at a glance
| Item | Status |
|---|---|
| SOC 2 Type I | 🟢 Report available |
| SOC 2 Type II | 🟡 In progress |
| Halborn audit — MPC protocol | 🟡 In progress |
| Halborn audit — Mobile signer | 🟡 In progress |
| MPC security model (overview) | 🟢 Public |
| Architecture documentation | 🟢 Public |
| Threat model | 🔒 Under NDA |
| Full protocol specs & DR runbooks | 🔒 Under NDA |
| Continuous internal red team | 🟢 Active |
| Bug bounty program | ⚪ Planned |
Independent assessments
| Assessment | Auditor | Scope | Status | Expected |
|---|---|---|---|---|
| SOC 2 Type I | to be announced | Org-wide controls (security, availability, confidentiality) | Report available | Issued 2026 |
| SOC 2 Type II | same auditor | Operating effectiveness across the audit window | In progress | 2027 |
| MPC Protocol Audit | Halborn | DKG, threshold signing, share refresh, share recovery | In progress | Q3 2026 |
| Mobile Signer Audit | Halborn | iOS and Android signer applications, on-device key share storage | In progress | Q3 2026 |
| Internal Red Team | The Vault Security | Backend services, infrastructure, identity & access | Continuous | Ongoing |
Final reports are made available under NDA to qualified prospects and customers. See Request reports below.
Halborn is a Tier-1 security firm with prior MPC and wallet engagements across the industry. We selected them specifically to assess the components that matter most for custody: the cryptographic protocol implementation and the mobile signer that holds an end-user key share.
What you can verify today
We publish our security model and architecture openly at a posture level. The full protocol specifications, threat model, and operational runbooks are shared under NDA with qualified prospects and customers.
Cryptographic protocols, threshold scheme, attack scenarios, and security guarantees.
MPC Security ModelDomain boundaries, trust zones, and security perimeters across the Client, Edge, Application, MPC Signing, and Blockchain layers.
Solution ArchitectureMonitoring, backup, disaster recovery, and upgrade practices.
OperationsHash-chained, Merkle-sealed, WORM-backed audit trail with integrity controls.
Immutable Audit LoggingMutual TLS, zero-trust networking between services, certificate lifecycle.
Network SecurityCryptographic foundations
The Vault uses threshold MPC. No single party — including The Vault itself — holds a complete private key at any point in a wallet’s lifecycle.
- Threshold scheme. Default 3-of-4; configurable per deployment.
- Protocols. Distributed Key Generation, threshold signing, proactive share refresh, and verifiable recovery. The protocol-level detail lives in the MPC security model.
- Key share storage. Mobile signer shares are stored encrypted at rest in the device’s secure storage; the encryption key is held in the OS secure storage (iOS Keychain / Android Keystore, hardware-backed — StrongBox / Secure Enclave — where the device provides it).
- Confidential computing. When TEE mode is enabled, the server signer workloads run in hardware TEEs (Intel TDX) with remote attestation before any key share is delivered. The coordinator holds no key material and runs as a standard service.
- Transport security. All inter-service traffic uses mutual TLS. MPC signer-to-signer messages are end-to-end encrypted with the Noise Protocol, relayed through the coordinator, which cannot read them.
- Audit integrity. Every privileged action writes to a hash-chained, append-only audit log.
The full cryptographic specification is the subject of the Halborn MPC and Mobile Signer audits currently in flight.
Compliance & data handling
| Topic | Status |
|---|---|
| Data residency | Configurable per deployment — see Deployment Sovereignty |
| Sub-processors | List in preparation — available on request |
| Privacy / DPA | Available on request |
| Penetration testing | Continuous internal red-team coverage; external pen test scheduled post-SOC 2 Type I |
| Blockchain screening | On the roadmap — see below |
| Insurance | Under evaluation |
Roadmap
We update this page whenever a milestone moves.
Request reports
The following are available under NDA to qualified prospects and customers:
- SOC 2 Type I report
- Halborn audit reports — MPC protocol and Mobile signer (once published)
- Penetration test summary
- Data Processing Agreement
- Sub-processor list
- Architecture brief
Contact security@<your-domain> or your account team to request.